From ea800ca1ec29fa13c3f13b2a17d51654d3f34a7b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 10 Jun 2024 15:32:51 +0000 Subject: [PATCH] Publish Advisories GHSA-8vmr-gjcv-vm3c GHSA-7qxh-m238-859c GHSA-8f4h-35jg-wp7g GHSA-8xp7-8ggj-xfq4 GHSA-9hrm-r87r-gq63 GHSA-9mrw-6xpv-33mx GHSA-ccrh-57hj-rh5r GHSA-grwc-qr6v-mgmv GHSA-hgc2-p5rv-xww2 GHSA-jh77-xp2v-pxpp GHSA-mhj4-vrcv-x4xc GHSA-mx85-w6rx-pfvf GHSA-rmff-fqq9-pc3q GHSA-vxpp-6299-mxw3 --- .../GHSA-8vmr-gjcv-vm3c.json | 2 +- .../GHSA-7qxh-m238-859c.json | 35 +++++++++++++++++ .../GHSA-8f4h-35jg-wp7g.json | 35 +++++++++++++++++ .../GHSA-8xp7-8ggj-xfq4.json | 38 +++++++++++++++++++ .../GHSA-9hrm-r87r-gq63.json | 35 +++++++++++++++++ .../GHSA-9mrw-6xpv-33mx.json | 38 +++++++++++++++++++ .../GHSA-ccrh-57hj-rh5r.json | 35 +++++++++++++++++ .../GHSA-grwc-qr6v-mgmv.json | 35 +++++++++++++++++ .../GHSA-hgc2-p5rv-xww2.json | 35 +++++++++++++++++ .../GHSA-jh77-xp2v-pxpp.json | 35 +++++++++++++++++ .../GHSA-mhj4-vrcv-x4xc.json | 35 +++++++++++++++++ .../GHSA-mx85-w6rx-pfvf.json | 38 +++++++++++++++++++ .../GHSA-rmff-fqq9-pc3q.json | 35 +++++++++++++++++ .../GHSA-vxpp-6299-mxw3.json | 2 +- 14 files changed, 431 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8f4h-35jg-wp7g/GHSA-8f4h-35jg-wp7g.json create mode 100644 advisories/unreviewed/2024/06/GHSA-8xp7-8ggj-xfq4/GHSA-8xp7-8ggj-xfq4.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9hrm-r87r-gq63/GHSA-9hrm-r87r-gq63.json create mode 100644 advisories/unreviewed/2024/06/GHSA-9mrw-6xpv-33mx/GHSA-9mrw-6xpv-33mx.json create mode 100644 advisories/unreviewed/2024/06/GHSA-ccrh-57hj-rh5r/GHSA-ccrh-57hj-rh5r.json create mode 100644 advisories/unreviewed/2024/06/GHSA-grwc-qr6v-mgmv/GHSA-grwc-qr6v-mgmv.json create mode 100644 advisories/unreviewed/2024/06/GHSA-hgc2-p5rv-xww2/GHSA-hgc2-p5rv-xww2.json create mode 100644 advisories/unreviewed/2024/06/GHSA-jh77-xp2v-pxpp/GHSA-jh77-xp2v-pxpp.json create mode 100644 advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json create mode 100644 advisories/unreviewed/2024/06/GHSA-mx85-w6rx-pfvf/GHSA-mx85-w6rx-pfvf.json create mode 100644 advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json diff --git a/advisories/unreviewed/2023/05/GHSA-8vmr-gjcv-vm3c/GHSA-8vmr-gjcv-vm3c.json b/advisories/unreviewed/2023/05/GHSA-8vmr-gjcv-vm3c/GHSA-8vmr-gjcv-vm3c.json index d85227d483d..a39d94bff7a 100644 --- a/advisories/unreviewed/2023/05/GHSA-8vmr-gjcv-vm3c/GHSA-8vmr-gjcv-vm3c.json +++ b/advisories/unreviewed/2023/05/GHSA-8vmr-gjcv-vm3c/GHSA-8vmr-gjcv-vm3c.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json b/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json new file mode 100644 index 00000000000..ba96ea3110e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-7qxh-m238-859c/GHSA-7qxh-m238-859c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qxh-m238-859c", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2022-45168" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the TOTP.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45168" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8f4h-35jg-wp7g/GHSA-8f4h-35jg-wp7g.json b/advisories/unreviewed/2024/06/GHSA-8f4h-35jg-wp7g/GHSA-8f4h-35jg-wp7g.json new file mode 100644 index 00000000000..d2b55e40196 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8f4h-35jg-wp7g/GHSA-8f4h-35jg-wp7g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f4h-35jg-wp7g", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-35306" + ], + "details": "OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35306" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-8xp7-8ggj-xfq4/GHSA-8xp7-8ggj-xfq4.json b/advisories/unreviewed/2024/06/GHSA-8xp7-8ggj-xfq4/GHSA-8xp7-8ggj-xfq4.json new file mode 100644 index 00000000000..882fc3eb903 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-8xp7-8ggj-xfq4/GHSA-8xp7-8ggj-xfq4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xp7-8ggj-xfq4", + "modified": "2024-06-10T15:31:03Z", + "published": "2024-06-10T15:31:03Z", + "aliases": [ + "CVE-2024-4403" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their knowledge, by sending specially crafted CSRF forms. This issue affects the installation process, including the installation of Binding zoo and Models zoo, by unexpectedly resetting programs. The vulnerability is due to the lack of CSRF protection in the affected function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4403" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c9dd6d2f-d83a-488b-9443-d4200c010851" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9hrm-r87r-gq63/GHSA-9hrm-r87r-gq63.json b/advisories/unreviewed/2024/06/GHSA-9hrm-r87r-gq63/GHSA-9hrm-r87r-gq63.json new file mode 100644 index 00000000000..129fccfb175 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9hrm-r87r-gq63/GHSA-9hrm-r87r-gq63.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hrm-r87r-gq63", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-35307" + ], + "details": "Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35307" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9mrw-6xpv-33mx/GHSA-9mrw-6xpv-33mx.json b/advisories/unreviewed/2024/06/GHSA-9mrw-6xpv-33mx/GHSA-9mrw-6xpv-33mx.json new file mode 100644 index 00000000000..c33fd0d616e --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-9mrw-6xpv-33mx/GHSA-9mrw-6xpv-33mx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mrw-6xpv-33mx", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-5785" + ], + "details": "Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability could allow an authenticated user to execute commands inside the router by making a POST request to the URL “/boaform/admin/formUserTracert”.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5785" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-comtrend-router" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ccrh-57hj-rh5r/GHSA-ccrh-57hj-rh5r.json b/advisories/unreviewed/2024/06/GHSA-ccrh-57hj-rh5r/GHSA-ccrh-57hj-rh5r.json new file mode 100644 index 00000000000..b65cd079bec --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-ccrh-57hj-rh5r/GHSA-ccrh-57hj-rh5r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccrh-57hj-rh5r", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2022-45176" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45176" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-grwc-qr6v-mgmv/GHSA-grwc-qr6v-mgmv.json b/advisories/unreviewed/2024/06/GHSA-grwc-qr6v-mgmv/GHSA-grwc-qr6v-mgmv.json new file mode 100644 index 00000000000..c7dfa3d4756 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-grwc-qr6v-mgmv/GHSA-grwc-qr6v-mgmv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grwc-qr6v-mgmv", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-36531" + ], + "details": "nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36531" + }, + { + "type": "WEB", + "url": "https://mat4mee.notion.site/Module-upload-in-nukeViet-leads-to-RCE-01ff3ff4c80d402d8c7c8a2b15a24c33" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-hgc2-p5rv-xww2/GHSA-hgc2-p5rv-xww2.json b/advisories/unreviewed/2024/06/GHSA-hgc2-p5rv-xww2/GHSA-hgc2-p5rv-xww2.json new file mode 100644 index 00000000000..f79b4a7e5a8 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-hgc2-p5rv-xww2/GHSA-hgc2-p5rv-xww2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgc2-p5rv-xww2", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-35304" + ], + "details": "System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35304" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jh77-xp2v-pxpp/GHSA-jh77-xp2v-pxpp.json b/advisories/unreviewed/2024/06/GHSA-jh77-xp2v-pxpp/GHSA-jh77-xp2v-pxpp.json new file mode 100644 index 00000000000..fe0a6e81a0a --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-jh77-xp2v-pxpp/GHSA-jh77-xp2v-pxpp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh77-xp2v-pxpp", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-35305" + ], + "details": "Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35305" + }, + { + "type": "WEB", + "url": "https://pandorafms.com/en/security/common-vulnerabilities-and-exposures" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json b/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json new file mode 100644 index 00000000000..a3920fb787b --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mhj4-vrcv-x4xc/GHSA-mhj4-vrcv-x4xc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhj4-vrcv-x4xc", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-36528" + ], + "details": "nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36528" + }, + { + "type": "WEB", + "url": "https://mat4mee.notion.site/2-bug-chains-in-nukeViet-lead-to-RCE-bdd42b20b05a448fbe87c752b41bb15f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-mx85-w6rx-pfvf/GHSA-mx85-w6rx-pfvf.json b/advisories/unreviewed/2024/06/GHSA-mx85-w6rx-pfvf/GHSA-mx85-w6rx-pfvf.json new file mode 100644 index 00000000000..8b248b3301c --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-mx85-w6rx-pfvf/GHSA-mx85-w6rx-pfvf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx85-w6rx-pfvf", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-5786" + ], + "details": "Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5786" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-comtrend-router" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json new file mode 100644 index 00000000000..3c252b60a50 --- /dev/null +++ b/advisories/unreviewed/2024/06/GHSA-rmff-fqq9-pc3q/GHSA-rmff-fqq9-pc3q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmff-fqq9-pc3q", + "modified": "2024-06-10T15:31:02Z", + "published": "2024-06-10T15:31:02Z", + "aliases": [ + "CVE-2024-36972" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock.\n\nBilly Jheng Bing-Jhong reported a race between __unix_gc() and\nqueue_oob().\n\n__unix_gc() tries to garbage-collect close()d inflight sockets,\nand then if the socket has MSG_OOB in unix_sk(sk)->oob_skb, GC\nwill drop the reference and set NULL to it locklessly.\n\nHowever, the peer socket still can send MSG_OOB message and\nqueue_oob() can update unix_sk(sk)->oob_skb concurrently, leading\nNULL pointer dereference. [0]\n\nTo fix the issue, let's update unix_sk(sk)->oob_skb under the\nsk_receive_queue's lock and take it everywhere we touch oob_skb.\n\nNote that we defer kfree_skb() in manage_oob() to silence lockdep\nfalse-positive (See [1]).\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor write access in kernel mode\n PF: error_code(0x0002) - not-present page\nPGD 8000000009f5e067 P4D 8000000009f5e067 PUD 9f5d067 PMD 0\nOops: 0002 [#1] PREEMPT SMP PTI\nCPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc5-00191-gd091e579b864 #110\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nWorkqueue: events delayed_fput\nRIP: 0010:skb_dequeue (./include/linux/skbuff.h:2386 ./include/linux/skbuff.h:2402 net/core/skbuff.c:3847)\nCode: 39 e3 74 3e 8b 43 10 48 89 ef 83 e8 01 89 43 10 49 8b 44 24 08 49 c7 44 24 08 00 00 00 00 49 8b 14 24 49 c7 04 24 00 00 00 00 <48> 89 42 08 48 89 10 e8 e7 c5 42 00 4c 89 e0 5b 5d 41 5c c3 cc cc\nRSP: 0018:ffffc900001bfd48 EFLAGS: 00000002\nRAX: 0000000000000000 RBX: ffff8880088f5ae8 RCX: 00000000361289f9\nRDX: 0000000000000000 RSI: 0000000000000206 RDI: ffff8880088f5b00\nRBP: ffff8880088f5b00 R08: 0000000000080000 R09: 0000000000000001\nR10: 0000000000000003 R11: 0000000000000001 R12: ffff8880056b6a00\nR13: ffff8880088f5280 R14: 0000000000000001 R15: ffff8880088f5a80\nFS: 0000000000000000(0000) GS:ffff88807dd80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000006314000 CR4: 00000000007506f0\nPKRU: 55555554\nCall Trace:\n \n unix_release_sock (net/unix/af_unix.c:654)\n unix_release (net/unix/af_unix.c:1050)\n __sock_release (net/socket.c:660)\n sock_close (net/socket.c:1423)\n __fput (fs/file_table.c:423)\n delayed_fput (fs/file_table.c:444 (discriminator 3))\n process_one_work (kernel/workqueue.c:3259)\n worker_thread (kernel/workqueue.c:3329 kernel/workqueue.c:3416)\n kthread (kernel/kthread.c:388)\n ret_from_fork (arch/x86/kernel/process.c:153)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:257)\n \nModules linked in:\nCR2: 0000000000000008", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36972" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9841991a446c87f90f66f4b9fee6fe934c1336a2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-06-10T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-vxpp-6299-mxw3/GHSA-vxpp-6299-mxw3.json b/advisories/unreviewed/2024/06/GHSA-vxpp-6299-mxw3/GHSA-vxpp-6299-mxw3.json index ecace9df3d8..ede95512616 100644 --- a/advisories/unreviewed/2024/06/GHSA-vxpp-6299-mxw3/GHSA-vxpp-6299-mxw3.json +++ b/advisories/unreviewed/2024/06/GHSA-vxpp-6299-mxw3/GHSA-vxpp-6299-mxw3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vxpp-6299-mxw3", - "modified": "2024-06-10T12:30:42Z", + "modified": "2024-06-10T15:31:02Z", "published": "2024-06-09T21:30:34Z", "aliases": [ "CVE-2024-4577"